Privacy Policy
Effective Date: May 31, 2026
Last Updated: May 31, 2026
Fantasy AI Scout ("we," "our," or "the App") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal information when you use our application and services.
1. Data Collection Practices
We collect the following categories of personal data to provide and improve our services:
Information You Provide
- Account Information: Email address, name, and password (for email/password registration) or profile information from social login providers (Google, Facebook, Instagram, Apple).
- League Data: Fantasy league settings, scoring rules, roster configurations, and draft preferences imported from Yahoo Fantasy Sports.
- Chat History: Messages and queries you submit to the AI assistant, including player questions and draft-related conversations.
- Draft Data: Your draft picks, roster selections, and draft session history.
Information Collected Automatically
- Usage Data: Pages visited, features used, session duration, and interaction patterns within the application.
- Device Information: Device type, operating system, browser type, and screen resolution for responsive design optimization.
- Performance Data: Page load times, error logs, and application performance metrics.
Why We Collect This Data
- To authenticate your identity and secure your account.
- To provide personalized draft recommendations based on your league settings.
- To maintain conversation context for the AI assistant.
- To track and display your draft progress in real time.
- To improve application performance and user experience.
2. Data Retention Policies
We retain your data only as long as necessary to provide our services and fulfill the purposes described in this policy:
- Account Information: Retained for the lifetime of your account. Deleted within 30 days of account deletion request.
- Chat History: Retained for the duration of your active session and up to 90 days for context continuity. Older messages are automatically purged.
- Draft Data: Retained for the current fantasy football season plus one additional season for historical reference. Older draft data is deleted automatically.
- League Settings: Retained while your Yahoo Fantasy account is connected. Removed within 7 days of disconnecting your Yahoo account.
- Usage and Performance Data: Aggregated and anonymized after 12 months. Raw data is deleted after 12 months.
- Authentication Tokens: Yahoo Fantasy API OAuth tokens are stored encrypted and automatically expire per Yahoo's token lifecycle. Expired tokens are deleted immediately.
3. Third-Party Data Sharing
We share your data with the following third-party services solely to provide application functionality:
Yahoo Fantasy Sports API
- Data Shared: Your Yahoo OAuth credentials (securely transmitted) to retrieve your league settings, player statistics, and roster information.
- Purpose: To import your league context and provide personalized recommendations.
- Data Flow: We read data from Yahoo; we do not write or modify your Yahoo Fantasy data.
Amazon Bedrock (AI Service)
- Data Shared: Your chat messages and queries are sent to Amazon Bedrock's Claude AI model for processing.
- Purpose: To generate AI-powered fantasy football recommendations and responses.
- Data Handling: Amazon Bedrock does not use your data to train models. Queries are processed in real time and not stored by Amazon beyond the request lifecycle.
Amazon Web Services (AWS) Infrastructure
- Data Stored: All application data is stored on AWS infrastructure (DynamoDB, S3, Secrets Manager) in the US East (Ohio) region.
- Security: Data is encrypted at rest and in transit. API credentials are stored in AWS Secrets Manager with per-user encryption.
Authentication Providers
- Services: Google, Facebook, Instagram, and Apple (for social login).
- Data Shared: Standard OAuth authentication flow. We receive your email address and basic profile information from these providers.
- Purpose: To verify your identity and create or link your account.
We do not sell your personal data. We do not share your data with advertisers or data brokers. Data is shared only with the services listed above and only to the extent necessary to provide application functionality.
4. Your Rights
You have the following rights regarding your personal data:
Access Your Data
You can request a complete copy of all personal data we hold about you. We will provide this data in a machine-readable format (JSON) within 30 days of your request.
Export Your Data
You can export your draft history, chat history, and league settings at any time through the application settings. Exported data is provided in JSON format for portability.
Delete Your Data
You can request deletion of your account and all associated data. Upon request:
- Your account and profile information will be deleted within 30 days.
- All chat history, draft data, and league settings will be permanently removed.
- Yahoo Fantasy API tokens will be revoked and deleted immediately.
- Anonymized, aggregated usage data may be retained as it cannot be linked back to you.
Correct Your Data
You can update your account information (email, name) at any time through the application settings. League settings can be manually overridden within the app.
Withdraw Consent
You can disconnect your Yahoo Fantasy account at any time, which will stop data retrieval from Yahoo. You can also delete your account entirely to withdraw all consent for data processing.
How to Exercise Your Rights
To exercise any of these rights, you can:
- Use the in-app settings to export or delete your data.
- Contact us at privacy@fantasyaiscout.com.
We will respond to all data requests within 30 days.
5. Additional Information
Security Measures
We implement industry-standard security measures including:
- Encryption at rest and in transit (TLS 1.2+).
- Per-user encryption for API credentials via AWS Secrets Manager.
- Account lockout after 5 consecutive failed login attempts.
- Regular security audits and vulnerability assessments.
Children's Privacy
Fantasy AI Scout is not intended for use by children under the age of 13. We do not knowingly collect personal data from children under 13.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via in-app notification or email. Continued use of the application after changes constitutes acceptance of the updated policy.
Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at: